State machine · 08 of 10 · Autonomy

Autonomy is earned per alert class, and revocable

Each alert class climbs one rung at a time on measured evidence. Any regression steps it back down, and a policy violation trips a breaker that has to be reviewed before it can climb again.

Autonomy is earned per alert class, and revocable State machine with four states: shadow, approve to run, auto-run and frozen. Promotion needs measured evidence at each step, rollbacks and human overrides demote, and a policy violation freezes the class until it is reviewed and re-earned. NEW CLASS≥95% MATCHCLEAN RUNSVIOLATIONROLLBACK · SLO BURNHUMAN OVERRIDESREVIEW + FIX, THEN RE-EARNShadowagent proposes, human actsApprove to runhuman clicks, agent runsAuto-runverify + auto-rollbackFrozencircuit breaker trippedIrreversible actions, and alert classes with no verifier, never leave Approve to run.LEGENDEarned levelCircuit breakerLevelPromoteDemoteRecover

Requirement

Push autonomous remediation into the paths that page people today: alerts that resolve themselves, and a first responder that is an agent with a hypothesis already tested.

Promotion criteria (proposed)

  • Shadow to approve: proposals match what the human actually did, at least 95% over a fixed window.
  • Approve to auto: a run of clean executions with zero rollbacks.
  • Demotion is automatic; promotion is a reviewed decision.

Evidence and gap

Built in Hangar: HolmesGPT AI-triage on alerts. Your own burns: an order-api prod wipe and a provider restart that caused real data loss are exactly why this ladder has a breaker and a "never" tier. Proposal only: the promotion tracker.

Hangar · reference architecture